logo

Critical—9 Vulnerabilities in Orthanc DICOM Servers Threaten Medical Data Integrity

ID: 568fe7c0-a1ba-5793-ba83-fe662f0093b8

STIX ID: report--568fe7c0-a1ba-5793-ba83-fe662f0093b8

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-14

Date Updated: 2026-04-23

Author: Ddos

...
...

Orthanc (≤1.12.10) contains nine critical vulnerabilities—notably CVE-2026-5438 (gzip decompression bomb), CVE-2026-5440 (unbounded Content-Length), and CVE-2026-5442/5443 (heap buffer overflows in image decoding)—that can crash servers, disclose heap-resident data (including private DICOM content), and under some conditions enable remote code execution. The advisory warns of persistent malicious DICOM content that may be stored and later re-triggered; recommended mitigations are immediate upgrade to Orthanc 1.12.11, limiting upload/processing exposure to trusted networks, and auditing configurations and deployment guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.